A €200 Fine with Wider Lessons: Filming, Health Data and the GDPR
8th September 2026
The Austrian Data Protection Authority (DSB) recently fined a medical student €200 for filming a hospital patient with dementia and sharing the video with a fellow student. The DSB found that both the recording and the disclosure amounted to unlawful processing of health data. The number will not make many headlines. But the case is a useful reminder of how easily an ordinary interaction with a phone becomes a serious breach, and individuals, not just controllers are liable for their actions; although this was a decision made by an EU Regulator, the ICO would be highly likely to reach a similar conclusion.
Filming is processing
Under Article 4(2) of the UK GDPR, ‘processing’ means any operation performed on personal data, and both ‘recording’ and ‘disclosure by transmission, dissemination or otherwise making available’ are explicitly listed. A video, regardless of the device it is displayed on, showing an identifiable person is personal data; sharing it with a colleague, however informally, is a disclosure. Both are processing, and both need a lawful basis. There is no informal-recording exemption, and there is certainly no ‘I was only showing my friend’ exemption. If a person appears in the footage, they are the data subject and their rights apply in full.
‘It was just my own phone’
The obvious objection is that the student was acting personally, on their own device, and not for any employer. Article 2(2)(a) of the UK GDPR does exclude processing by an individual in the course of a purely personal or household activity, but the exemption must be read narrowly. Filming a patient met through a clinical placement is not a domestic activity, and passing the footage to someone outside your household takes it further still. Staff who record people they meet through work are unlikely to shelter behind it.
An example of personal use would be your Ring doorbell. It is being used to record your footpath, however, if you upload that footage to social media and an individual is identifiable, then the exemption no longer applies and you need a lawful basis.
Health data and the double lock
The Austrian case turned on the additional layer that applies here. Because the video showed a patient in a hospital, it fell within Article 9 of the UK GDPR: special category data. To process it lawfully, a controller needs both an Article 6 basis and an Article 9 condition. Ordinary consent from an adult is problematic where the data subject is a patient with dementia, whose capacity to consent, and to understand what disclosure means, cannot be presumed. Without a robust Article 9 condition, the processing is unlawful whatever the recording device.
What it means for UK organisations
This is not just a healthcare story. Care homes and hospitals sit at the sharpest end, but the same analysis applies to schools recording pupils at events, employers filming team-building sessions, and any organisation photographing customers or the public. There is no reason to think the ICO would analyse it differently: recording is processing, sharing is disclosure, and special category information brings extra obligations on top.
Practical safeguards
The actions needed to protect an organisation is neither dramatic nor complicated. Write a short, clear policy on staff use of personal devices at work, and train people that a recording, be that an audio or video recording on another individual is not a private note. Restrict recording where patients, pupils or vulnerable individuals may appear, or require it to be authorised and documented. Make sure your Appropriate Policy Document (required if you are relying on substantial public interest conditions) covers the special category processing you actually do. Small, deliberate steps prevent almost every case that starts like this one.
And a final short note on developing technologies, this case revolved around a video recording using a standard smartphone, the issues will be the same with wearable technology, the recording of which is often invisible, and so more problematic – try and future proof your policy and so do not just limit to smartphone recordings.
How Griffin House Consultancy Can Help
We help organisations write policies that staff actually follow, train teams on the practical realities of Article 9, and audit the operational reality against the paperwork. Whether you are in health, social care, education, or an office wondering about team photos on LinkedIn, get in touch with us at Griffin House Consultancy, or call us on 01673 885533.
Author: Mike Martin LLM
Mike is an information rights law specialist and one of the Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.